A troubling story is unfolding in the Hyperliquid ecosystem, directly impacting user security. One asset holder on the HyperSwap decentralized exchange, operating on the HyperEVM blockchain, reported the theft of funds totaling approximately $12,000. Analysis of blockchain data allows for a full reconstruction of this incident, which is rooted in a classic, yet no less dangerous, phishing attack.
How It All Began
The affected user had deposited their tokens into a HyperSwap liquidity pool. Their share in the pool was confirmed by a unique NFT certificate. It all started when, on social network X (formerly Twitter), they came across a post allegedly published from the official HyperSwap account. The post contained a link to an "airdrop" — a free token distribution. However, behind this link was not a drop, but a crypto drainer — a tool designed to empty wallets.
It is important to emphasize: HyperSwap is an independent project built on the Hyperliquid blockchain. Just as with Ethereum and Uniswap, the Hyperliquid team does not manage third-party applications on its network. This is a fundamental point, which, however, does not absolve the ecosystem of responsibility for user security.
The Unnoticed Impersonation
The key element of the attack was account impersonation. The post was not published by the exchange's official account, but by a lookalike. The fake account's name differed from the real one by just a couple of characters. The user, not noticing this difference, took the fake at face value and clicked the link to a phishing clone site, which was visually indistinguishable from the original.
Accidental Confirmation
On the fake site, the user connected their wallet and, believing they were simply checking eligibility for free tokens, confirmed a transaction. In reality, this action granted the scammer permission to manage their token, which confirmed their share in the liquidity pool. Externally, this confirmation was no different from regular operations on legitimate services, so the trick went unnoticed until the funds were debited.
The Theft Took Less Than Two Minutes
The active phase of the theft occurred between 20:21 and 20:23 UTC on June 29, 2026. First, the scammer address, flagged by the security service HashDit as Fake_Phishing3746335, used the obtained access and transferred the NFT containing the victim's deposit to their own wallet. This operation was initiated and paid for by the attacker themselves — the victim was no longer signing anything at this point.
Then, the scammer withdrew the deposited coins from the NFT: approximately 3935 USDC and 116 WHYPE, totaling around $12,100. After that, using the legitimate cross-chain bridge service LI.FI, they consolidated all stolen funds into a single HYPE token and transferred approximately $12,300 from the HyperEVM network to the Ethereum network.
How the Traces Were Spotted
On the Ethereum network, the funds arrived at an address that had been created shortly before. It was used exactly once: it received the funds, almost immediately forwarded them in a single transaction, and remained empty. Such a one-time "transit" wallet is a typical element in the money laundering chain.
Note an important nuance: to withdraw the funds, the scammer did not use some hacking tool, but an ordinary, legitimate service. This complicates tracking and can create a false impression for the victim that the service or exchange itself is to blame. In reality, this is a deliberate part of the scheme.
The scammer address was active for about a month and was linked to approximately 25 different wallets. This indicates that we are not dealing with a random incident, but with a well-established, streamlined scheme.
Complaints Against the Project
Upon discovering the loss, the user attempted to contact the project team to have the suspicious link removed. According to screenshots, the link had been active in messages since June 26. According to the victim, they tried various ways to warn the Hyperliquid team about the scam, but received no response.
The only active communication channel with HyperSwap at that time was Discord, but the link to it turned out to be invalid. Attempts to bring the issue to the attention of the Hyperliquid ecosystem team were also unsuccessful. The victim speculated that HyperSwap employees might be involved in the theft or intentionally covering it up.
How to Protect Yourself from Scams
- Access exchanges and services only via addresses from official sources, not from links in posts or direct messages on social media.
- Check the account name letter by letter: scammers create platform lookalikes differing by one or two letters.
- Do not confirm operations in your wallet whose meaning you don't understand, especially granting permissions to manage tokens and deposits.
- Regularly check and revoke granted permissions through trusted services, typing their address manually.
- If you suspect theft, revoke all permissions from the compromised wallet as quickly as possible and transfer remaining assets to a new one.
Expert Analysis: This incident is a stark example that even in a decentralized environment, the user remains the primary link in security. The responsibility for checking links and permissions lies solely with us. Projects, especially in their early stages, should pay more attention to monitoring their brand on social media and responding promptly to phishing threats; otherwise, reputational damage could prove far more severe than financial losses.